On this platform, a user could submit a prompt to the automation API and later retrieve the saved result by its run ID. That result included the agent's answer and usage data.
A separate feedback endpoint accepted a score and comment linked to the same run ID. We tested whether those two endpoints checked which tenant owned the run.
Description
With accounts on two tenants:
- A user on tenant A submits a headless run and receives a run identifier.
- A user on tenant B requests
GET /v1/automation/runs/{run_id}using tenant A's identifier and receives the full run result. - Tenant B posts feedback against tenant A's run and receives a feedback identifier.
Impact
Tenant B read tenant A's run result. It included the agent's answer to A's query, token usage and timestamps. In this test the answer contained job details returned for tenant A.
The feedback request also returned success and a feedback ID, but its persistence was not checked.
Tenant B needed to know the run ID. We did not test whether run IDs could be discovered or guessed.
Steps to reproduce
Auth context: a scheduler-tier account on tenant A and an admin-tier account on tenant B.
-
As tenant A, submit a headless run querying the status of a known job, and note the returned run identifier and the reported token consumption.
-
As tenant B, request that run:
GET /v1/automation/runs/{tenant_a_run_id}
Authorization: Bearer <tenant-b-token>
Observed: 200 OK. The result summary and token consumption match the values returned to tenant A in step 1.
"result": {
"summary": "JOB-<id> is currently <status>. Type: <job-type>.
Location: <address>."
},
"usage": { "tokens_consumed": <n> }
- As tenant B, write feedback against the same run with a canary in the comment:
POST /v1/feedback
Authorization: Bearer <tenant-b-token>
Content-Type: application/json
{
"run_id": "{tenant_a_run_id}",
"score": 5,
"feedback": "positive",
"comment": "BOLA-XTENANT-TEST-<timestamp>"
}
Observed: 200 OK, with a feedback_id returned.
Remediation
On both endpoints, look up the run under the tenant in the authenticated session. Reject a request for another tenant's run before returning its result or accepting feedback linked to it.
